openapi: 3.0.1 info: title: Dfns Approvals Signatures API description: 'Representative OpenAPI description of the Dfns wallet-as-a-service and MPC key-management REST API. Covers programmable non-custodial wallets, MPC keys, transfers and transactions, signature generation, the policy engine and approvals, webhooks, permissions and authentication (including User Action Signing), service accounts, and blockchain network reads. Authentication uses an Authorization Bearer access token (from a service account token or a user login) plus, for sensitive mutating operations, a User Action Signature obtained via the User Action Signing challenge/complete flow and passed in the X-DFNS-USERACTION header.' contact: name: Dfns Support url: https://www.dfns.co/ termsOfService: https://www.dfns.co/terms-of-service version: '1.0' servers: - url: https://api.dfns.io description: Dfns production REST API (Europe / default) - url: https://api.uae.dfns.io description: Dfns production REST API (UAE region) security: - BearerAuth: [] AppId: [] tags: - name: Signatures description: Raw signature generation from keys. paths: /keys/{keyId}/signatures: post: operationId: generateKeySignature tags: - Signatures summary: Generate a signature from a key description: Produces a raw signature using a standalone MPC key. Requires a User Action Signature. security: - BearerAuth: [] AppId: [] UserAction: [] parameters: - in: path name: keyId required: true schema: type: string requestBody: required: true content: application/json: schema: type: object required: - kind properties: kind: type: string enum: - Hash - Message hash: type: string responses: '200': description: The signature request. content: application/json: schema: $ref: '#/components/schemas/SignatureRequest' components: schemas: SignatureRequest: type: object properties: id: type: string walletId: type: string status: type: string enum: - Pending - Executing - Signed - Confirmed - Failed - Rejected requestBody: type: object signature: type: object nullable: true properties: r: type: string s: type: string recid: type: integer encoded: type: string dateRequested: type: string format: date-time securitySchemes: BearerAuth: type: http scheme: bearer bearerFormat: JWT description: 'Access token issued to a service account or a logged-in user. Sent as `Authorization: Bearer `.' AppId: type: apiKey in: header name: X-DFNS-APPID description: The Dfns application (app) id the request is made on behalf of. UserAction: type: apiKey in: header name: X-DFNS-USERACTION description: A User Action Signature token proving the caller cryptographically signed the request payload. Required on sensitive mutating operations (transfers, signature generation, key/policy/permission changes).